CAS with REST API

37 views
Skip to first unread message

Hussein Emam

unread,
Dec 2, 2017, 5:26:23 AM12/2/17
to CAS Community
 I have a REST service that is called from a mobile application, Is it possible to authenticate the service against CAS ? is it safe to do this ?
Thanks

Andy Ng

unread,
Dec 3, 2017, 8:13:55 AM12/3/17
to CAS Community
Pretty sure what you want is this:https://apereo.github.io/cas/5.2.x/protocol/REST-Protocol.html

As for safety, since this REST implementation is included as an official features, the safety risk shouldn't be that high, your mileage may vary.

Moreover, you can always check the source code yourself to see to logic, if you have any doubt. I've look at it before and I think code is fine.

If you can modified the mobile application, then you might even consider opt for OAuth 2.0 or something else, if you really don't trust REST.

Hope this helps you

-Andy
Reply all
Reply to author
Forward
0 new messages